* [PATCH net] macsec: ignore inactive receive secure channels
@ 2026-10-08 8:26 Sung Byeongchan
2026-10-08 13:26 ` Sabrina Dubroca
0 siblings, 1 reply; 2+ messages in thread
From: Sung Byeongchan @ 2026-10-08 8:26 UTC (permalink / raw)
To: Sabrina Dubroca; +Cc: netdev
The receive path looks up an RXSC by SCI without checking its active flag.
An active child RXSA can therefore authenticate and deliver frames after
userspace has administratively disabled the RXSC.
Restrict the receive-only RCU lookup to active RXSCs. Keep the RTNL lookup
used for configuration unchanged so userspace can reactivate or remove an
inactive channel.
All three baseline runs delivered a valid protected frame while an
independent state dump reported the RXSC off. All three fixed runs rejected
the frame. RXSC reactivation and RXSA off/on controls retained their
expected behavior.
The demonstrated impact is a revocation and integrity-policy bypass. No
memory corruption or RCE/LPE primitive was observed.
This change was prepared with assistance from OpenAI Codex. I reviewed the
source change, test results, and this commit message.
Fixes: c09440f7dcb3 ("macsec: introduce IEEE 802.1AE driver")
Assisted-by: OpenAI Codex
Signed-off-by: Sung Byeongchan <tjdqudcks0424@naver.com>
---
drivers/net/macsec.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/macsec.c b/drivers/net/macsec.c
index 78a19b1346321..02157c97e0004 100644
--- a/drivers/net/macsec.c
+++ b/drivers/net/macsec.c
@@ -989,7 +989,7 @@ static struct macsec_rx_sc *find_rx_sc(struct macsec_secy *secy, sci_t sci)
struct macsec_rx_sc *rx_sc;
for_each_rxsc(secy, rx_sc) {
- if (rx_sc->sci == sci)
+ if (rx_sc->sci == sci && READ_ONCE(rx_sc->active))
return rx_sc;
}
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH net] macsec: ignore inactive receive secure channels
2026-10-08 8:26 [PATCH net] macsec: ignore inactive receive secure channels Sung Byeongchan
@ 2026-10-08 13:26 ` Sabrina Dubroca
0 siblings, 0 replies; 2+ messages in thread
From: Sabrina Dubroca @ 2026-10-08 13:26 UTC (permalink / raw)
To: Sung Byeongchan; +Cc: netdev
Hello,
This probably doesn't need to be called a bugfix that goes to net
(2554c08e16aa ("macsec: check the resolved SCI for duplicates") went
to net-next).
2026-10-08, 17:26:12 +0900, Sung Byeongchan wrote:
> The receive path looks up an RXSC by SCI without checking its active flag.
> An active child RXSA can therefore authenticate and deliver frames after
> userspace has administratively disabled the RXSC.
>
> Restrict the receive-only RCU lookup to active RXSCs. Keep the RTNL lookup
> used for configuration unchanged so userspace can reactivate or remove an
> inactive channel.
Function names please. I don't know why LLMs are so opposed to precise
references to the code.
This is a change of user-visible behavior. I don't think it matters
because this flag is probably unused (at least, it's unused by both
wpa_supplicant and MKAdaemon), but it's a change nonetheless and
deserves a mention in the commit message.
(it's one of those things that I implemented because it's in the spec,
but that I should have skipped in retrospect)
> All three baseline runs delivered a valid protected frame while an
> independent state dump reported the RXSC off. All three fixed runs rejected
> the frame. RXSC reactivation and RXSA off/on controls retained their
> expected behavior.
Out of curiosity: why 3 runs, what's different between them?
This would be worth a small selftest, since we don't have a lot of
traffic tests currently. Just something that does:
set up everything with active RXSCs
send a few packets, make sure they arrive
disable the RXSC
send a few packets, make sure they get dropped
re-enable the RXSC
send a few packets, make sure they arrive
(this would be a separate patch, see for example
https://lore.kernel.org/all/20261001-fix-macsec-duplicate-sci-v3-2-0f179fbe1f2d@gmail.com/)
--
Sabrina
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-08 13:26 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-08 8:26 [PATCH net] macsec: ignore inactive receive secure channels Sung Byeongchan
2026-10-08 13:26 ` Sabrina Dubroca
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox